Latest CVE Feed
-
5.0
MEDIUMCVE-2014-3695
markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (application crash) via a large length value in an emoticon response.... Read more
Affected Products : pidgin- Published: Oct. 29, 2014
- Modified: Apr. 12, 2025
-
6.4
MEDIUMCVE-2014-3694
The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates from SSL servers, which allows man-in... Read more
- Published: Oct. 29, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-3670
The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory corru... Read more
Affected Products : php- Published: Oct. 29, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3669
Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code... Read more
Affected Products : php- Published: Oct. 29, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3668
Buffer overflow in the date_from_ISO8601 function in the mkgmtime implementation in libxmlrpc/xmlrpc.c in the XMLRPC extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (applicat... Read more
Affected Products : php- Published: Oct. 29, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3051
The Internet Service Monitor (ISM) agent in IBM Tivoli Composite Application Manager (ITCAM) for Transactions 7.1 and 7.2 before 7.2.0.3 IF28, 7.3 before 7.3.0.1 IF30, and 7.4 before 7.4.0.0 IF18 does not verify X.509 certificates from SSL servers, which ... Read more
Affected Products : tivoli_composite_application_manager_for_transactions- Published: Oct. 29, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-6126
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.5.0 before CF03 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : websphere_portal- Published: Oct. 28, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-6125
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Portal 8.5.0 before CF03 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.... Read more
Affected Products : websphere_portal- Published: Oct. 28, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-4821
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 provides different web-server error codes depending on whether a requested file exists, which allows rem... Read more
Affected Products : websphere_portal- Published: Oct. 28, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-4814
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 does not properly detect recursion during entity expansion, which allows remote authenticated users to c... Read more
Affected Products : websphere_portal- Published: Oct. 28, 2014
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2014-4808
Unspecified vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 allows remote authenticated users to execute arbitrary code via unknown vec... Read more
Affected Products : websphere_portal- Published: Oct. 28, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3293
Cisco IOS 15.4(3)S0b on ASR901 devices makes incorrect decisions to use the CPU for IPv4 packet processing, which allows remote attackers to cause a denial of service (BGP neighbor flapping) by sending many crafted IPv4 packets, aka Bug ID CSCuo29736.... Read more
- Published: Oct. 28, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-8506
Multiple SQL injection vulnerabilities in Etiko CMS allow remote attackers to execute arbitrary SQL commands via the (1) page_id parameter to loja/index.php or (2) article_id parameter to index.php.... Read more
Affected Products : etiko_cms- Published: Oct. 28, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8505
Multiple cross-site scripting (XSS) vulnerabilities in Etiko CMS allow remote attackers to inject arbitrary web script or HTML via the (1) page_id parameter to loja/index.php or (2) article_id parameter to index.php.... Read more
Affected Products : etiko_cms- Published: Oct. 28, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4023
Cross-site scripting (XSS) vulnerability in tmui/dashboard/echo.jsp in the Configuration utility in F5 BIG-IP LTM, APM, ASM, GTM, and Link Controller 11.0.0 before 11.6.0 and 10.1.0 through 10.2.4, AAM 11.4.0 before 11.6.0, AFM and PEM 11.3.0 before 11.6.... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager big-ip_policy_enforcement_manager big-ip_edge_gateway +5 more products- Published: Oct. 28, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4586
Multiple cross-site scripting (XSS) vulnerabilities in the wp-football plugin 1.1 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the league parameter to (1) football_classification.php, (2) football_criteria.ph... Read more
Affected Products : wp-football- Published: Oct. 27, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2012-5580
Format string vulnerability in the print_proxies function in bin/proxy.c in libproxy 0.3.1 might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a proxy name, as de... Read more
Affected Products : libproxy- Published: Oct. 27, 2014
- Modified: Apr. 12, 2025
-
4.6
MEDIUMCVE-2012-1111
lightdm before 1.0.9 does not properly close file descriptors before opening a child process, which allows local users to write to the lightdm log or have other unspecified impact.... Read more
Affected Products : lightdm- Published: Oct. 27, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2011-2702
Integer signedness error in Glibc before 2.13 and eglibc before 2.13, when using Supplemental Streaming SIMD Extensions 3 (SSSE3) optimization, allows context-dependent attackers to execute arbitrary code via a negative length parameter to (1) memcpy-ssse... Read more
- Published: Oct. 27, 2014
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2010-5077
server/sv_main.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote attackers to cause a denial of service (network traffic amplification) via a spoofed (1) getstatus or (2) rcon request.... Read more
- Published: Oct. 27, 2014
- Modified: Apr. 12, 2025